SNORT ¼³Ä¡ ¹× ¿î¿µ
¼³Ä¡È¯°æÀº ´ÙÀ½°ú °°´Ù.
Glibc 2.1.3
libpcap 0.6.2
SNORT 1.8.2
SNORT¼³Ä¡
º»ÀÎÀº ÇÁ·Î±×·¥ ÀÚü¿¡ ´ëÇÑ ¼³¸íÀ» ¸¹ÀÌ ÇÏÁö´Â ¾Ê´Â´Ù.
ÀÚ½ÅÀÌ ¿øÇÒ¶§ ÇØ¾ß ÁýÁß·ÂÀ̳ª ÀÌÇØ·Â¿¡ Á¤Á¡¿¡ À̸£´Â °ÍÀÌ´Ù. - °©Àڱ⠶׵ýÁö ..
SNORT´Â IDS(Instrusion Detection System)ÀÌ´Ù.
Áï, ±âÁ¸ ¹æÈº®µîÀÌ ¿ÜºÎÀÇ Ä§ÀÔÀ» ¸·´Âµ¥ ÁßÁ¡À» µÎ¾ú´Ù¸é(iptables, tcp wrapper...),
ÀÌ ³ðÀº ħÀÔÇÏ·Á´Â °ÍÀ» ŽÁöÇϴµ¥ ÁßÁ¡À» µÎ¾ú´Ù. ÆÐŶ³»ÀÇ Æ¯Á¤ ºÎºÐÀÌ(ħÀÓÈçÀûÀ̶ó°í ÆÇ´ÜµÇ´Â)
¹ß°ßµÇ¸é À̸¦ ŽÁöÇÒ ¼ö ÀÖ´Ù. ÀÌ·± ƯÁ¤ ºÎºÐÀº °è¼Ó °»½ÅµÇ¾î¾ß ÇϹǷΠ·ê¼ÂÀ̶ó´Â º°µµÀÇ
ÆÄÀÏ·Î °è¼Ó °»½ÅµÇ¾î Á¦°øµÇ°í ÀÖ´Ù.
libpcap ¼³Ä¡
snort´Â libpcap¶óÀ̺귯¸®¸¦ »ç¿ëÇϹǷΠ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é ¼³Ä¡ÇØ ÁØ´Ù.
[root@ns /down]$ wget
http://www.tcpdump.org/daily/libpcap-current.tar.gz
[root@ns /down]# tar xvzf libpcap-current.tar.gz -C /usr/local/src
[root@ns /down]# cd /usr/local/src/libpcap-2001.11.03
[root@ns libpcap-2001.11.03]# ./configure
[root@ns libpcap-2001.11.03]# make
snort ¼³Ä¡
SNORT´Â
www.snort.org¿¡¼ ¹èÆ÷ÇÑ´Ù.
[root@ns /down]# wget
http://www.snort.org/releases/snort-1.8.2.tar.gz
[root@ns /down]# tar xvzf snort-1.8.2.tar.gz -C /usr/local/src
[root@ns /down]# cd /usr/local/src/snort-1.8.2/
[root@ns snort-1.8.2]# ./configure
[root@ns snort-1.8.2]# make
[root@ns snort-1.8.2]# make install
»ç¿ë
¹èÆ÷tar¿¡ SnortUsersManual.pdf¶ó´Â ¸Å´º¾óÀÌ µé¾î ÀÖÀ¸´Ï º¸¸é µÇ°Ú´Ù.
±×³É ½©ÇÁ·ÒÇÁÆ®¿¡¼ snort¶ó°í¸¸ ÀÔ·ÂÇÏ¿© ½ÇÇàÇØº¸ÀÚ.
[root@ns snort-1.8.2]# snort
Log directory = /var/log/snort
Initializing Network Interface eth0
using config file ./snort.conf
Initializing Preprocessors!
Initializing Plug-ins!
Initializating Output Plugins!
Parsing Rules file ./snort.conf
+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
No arguments to frag2 directive, setting defaults to:
Fragment timeout: 60 seconds
Fragment memory cap: 4194304 bytes
Stream4 config:
Stateful inspection: ACTIVE
Session statistics: INACTIVE
Session timeout: 30 seconds
Session memory cap: 8388608 bytes
State alerts: INACTIVE
Scan alerts: ACTIVE
Log Flushed Streams: INACTIVE
No arguments to stream4_reassemble, setting defaults:
Reassemble client: ACTIVE
Reassemble server: INACTIVE
Reassemble ports: 21 23 25 53 80 143 110 111 513
Reassembly alerts: ACTIVE
Back Orifice detection brute force: DISABLED
Using LOCAL time
882 Snort rules read...
882 Option Chains linked into 92 Chain Headers
0 Dynamic rules
+++++++++++++++++++++++++++++++++++++++++++++++++++
Rule application order: ->activation->dynamic->alert->pass->log
--== Initializing Snort ==--
Initializing Network Interface eth0
Decoding Ethernet on interface eth0
--== Initialization Complete ==--
-*> Snort! <*-
Version 1.8.2 (Build 86)
By Martin Roesch (
roesch@sourcefire.com,
www.snort.org)
Foreground·Î ½ÇÇàµÇ¾úÀ¸¹Ç·Î Á¾·áÇÏ·Á¸é Ctrl+C¸¦ ´©¸¥´Ù.
===============================================================================
Snort analyzed 1222 out of 1222 packets, dropping 0(0.000%) packets
Breakdown by protocol: Action Stats:
TCP: 484 (39.607%) ALERTS: 33
UDP: 109 (8.920%) LOGGED: 33
ICMP: 0 (0.000%) PASSED: 0
ARP: 375 (30.687%)
IPv6: 0 (0.000%)
IPX: 0 (0.000%)
OTHER: 253 (20.704%)
DISCARD: 0 (0.000%)
===============================================================================
Fragmentation Stats:
Fragmented IP Packets: 0 (0.000%)
Fragment Trackers: 0
Rebuilt IP Packets: 0
Frag elements used: 0
Discarded(incomplete): 0
Discarded(timeout): 0
Frag2 memory faults: 0
===============================================================================
TCP Stream Reassembly Stats:
TCP Packets Used: 484 (39.607%)
Stream Trackers: 41
Stream flushes: 1
Segments used: 1
Stream4 Memory Faults: 0
===============================================================================
Snort received signal 2, exiting
[root@ns snort-1.8.2]#
À§¿¡¼ º¸µíÀÌ ±âº»ÀûÀ¸·Î 882ÀÇ ·ê(rule)ÀÌ Á¦°øµÈ´Ù.
ÀÌ´Â Ãß°¡ÀûÀ¸·Î Á¤ÀÇµÉ ¼ö ÀÖÀ¸¹Ç·Î ·ê¼ÂÀÇ °³³äÀº Áß¿äÇÏ´Ù.
ruleset ¼³Ä¡
snortrules.tar.gz¿¡´Â snort¼³Á¤ÆÄÀÏÀÎ snort.confÆÄÀÏÀÌ Á¸ÀçÇÑ´Ù.
[root@ns /down]# wget
http://www.snort.org/downloads/snortrules.tar.gz
[root@ns /down]# tar xvzf snortrules.tar.gz -C /usr/local/bin
[root@ns /down]# cd /usr/local/bin/rules
snort.conf¿¡¼ ¼³Á¤
´ÙÀ½°ªµéÀ» ÀÚ½ÅÀÇ È¯°æ¿¡ ¸Â°Ô ÁöÁ¤ÇÏ°í ³ª¸ÓÁö´Â µðÆúÆ®·Î »ç¿ëÇÑ´Ù.
¹ÙÀÌ·¯½º(´Ô´Ù,..)·Î ÀÎÇØ ISS¿¡ ´ëÇÑ ·Î±×°¡ ¸¹À¸¹Ç·Î µð½ºÅ© Àý¾àÂ÷¿ø¿¡¼ ¾Æ¿¹ »©¹ö·È´Ù.
os°¡ ¸®´ª½ºÀ̹ǷΠÀÌ¿¡ ´ëÇÑ ÇÇÇØ´Â ¾øÀ»°ÍÀÌ´Ù.
var HOME_NET 211.41.23.0/24
preprocessor portscan-ignorehosts: $DNS_SERVERS
#include web-iis.rules
½ÇÇà
[root@ns src]# snort -D -b -A fast -c /usr/local/bin/rules/snort.conf
-D: µ¥¸ó¸ðµå
-b: textº¯ÈÁ¦°Å
-c: ¼³Á¤ÆÄÀÏ ÁöÁ¤
Å×½ºÆ®
È£½ºÆ® B¿¡¼ È£½ºÆ® A·Î Æ÷Æ®½ºÄµÀ» ÇØº»´Ù.
[È£½ºÆ®B]
[root@A /down]# nmap -O -sS 211.41.23.236
[È£½ºÆ®A]
/var/log/snort/alert
11/04-04:27:16.607990 [**] [1:618:1] INFO - Possible Squid Scan [**] [Classification: Attempted Information
Leak] [Priority: 2] {TCP} 211.41.23.252:37372 -> 211.41.23.236:3128
11/04-04:27:18.580974 [**] [100:1:1] spp_portscan: PORTSCAN DETECTED to port 25 from 211.41.23.252
(STEALTH) [**]
11/04-04:27:18.580209 [**] [111:12:1] spp_stream4: NMAP FINGERPRINT (stateful) detection [**] {TCP}
211.41.23.252:37382 -> 211.41.23.236:25
11/04-04:27:18.580257 [**] [1:628:1] SCAN nmap TCP [**] [Classification: Attempted Information Leak]
[Priority: 2] {TCP} 211.41.23.252:37384 -> 211.41.23.236:1
11/04-04:27:18.580282 [**] [111:10:1] spp_stream4: STEALTH ACTIVITY (nmap XMAS scan) detection [**]
{TCP} 211.41.23.252:37385 -> 211.41.23.236:1
11/04-04:27:21.380211 [**] [111:12:1] spp_stream4: NMAP FINGERPRINT (stateful) detection [**] {TCP}
211.41.23.252:37382 -> 211.41.23.236:25
11/04-04:27:21.380260 [**] [1:628:1] SCAN nmap TCP [**] [Classification: Attempted Information Leak]
[Priority: 2] {TCP} 211.41.23.252:37384 -> 211.41.23.236:1
11/04-04:27:21.380284 [**] [111:10:1] spp_stream4: STEALTH ACTIVITY (nmap XMAS scan) detection [**]
{TCP} 211.41.23.252:37385 -> 211.41.23.236:1
11/04-04:27:24.181210 [**] [100:2:1] spp_portscan: portscan status from 211.41.23.252: 3 connections
across 1 hosts: TCP(3), UDP(0) STEALTH [**]
11/04-04:27:24.180302 [**] [111:12:1] spp_stream4: NMAP FINGERPRINT (stateful) detection [**] {TCP}
211.41.23.252:37382 -> 211.41.23.236:25
11/04-04:27:24.180351 [**] [1:628:1] SCAN nmap TCP [**] [Classification: Attempted Information Leak]
[Priority: 2] {TCP} 211.41.23.252:37384 -> 211.41.23.236:1
11/04-04:27:24.180376 [**] [111:10:1] spp_stream4: STEALTH ACTIVITY (nmap XMAS scan) detection
[**] {TCP} 211.41.23.252:37385 -> 211.41.23.236:1
[root@ns snort]# cat portscan.log
Nov 4 04:27:24 211.41.23.252:37380 -> 211.41.23.236:25 NULL ********
Nov 4 04:27:21 211.41.23.252:37381 -> 211.41.23.236:25 NMAPID **U*P*SF
Nov 4 04:27:21 211.41.23.252:37385 -> 211.41.23.236:1 XMAS **U*P**F
[SNORT SNARF]
snort·Î±×ÆÄÀÏÀ» ºÐ¼®ÇØ À¥ÆäÀÌÁö¿¡¼ º¼ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
MRTG°°ÀÌ CRONÀ¸·Î µ¹·Á º»´Ù. ´Ü, mrtg°¡ º¸Åë 5ºÐÁÖ±â·Î µ¹¸®Áö¸¸, ÀÌ ³ðÀº 1ÀÏÁÖ±â·Î µ¹¸®´Â °ÍÀÌ ÁÁ°Ú´Ù.
ÀÌ ÅøÀº snort»çÀÌÆ®¿¡ ¸µÅ©µÇ¾î ÀÖ¾î ±¦ÂúÀº(?) ³ðÀ̶ó°í »ý°¢Çß´Ù.
ÇÏÁö¸¸... ÀÚ¿ø»ç¿ëÀÌ ³Ê¹« ¸¹´Ù. ¼¹ö»ç¾çÀÌ ¿Ø¸¸Å ¹ÞÃÄÁÖÁö ¾ÊÀ¸¸é Àý´ë µ¹¸®Áö ¸»¶ó.
¿¹) alert·Î±×Å©±â°¡ 11MÁ¤µµÀÏ ¶§ ½ÇÇàÇßÀ¸³ª, ³¡³¯ »ý°¢À» ¾ÈÇß´Ù.
topÀ¸·Î ÆÄ¾ÇÇÑ CPU, ¸Þ¸ð¸®»ç¿ë·®Àº °¢°¢ 90%ÀÌ»ó, 140MÀÌ»óÀ¸·Î ¼¹ö´Ù¿îÀÇ À§±â¸¦ ´À²¼´Ù.
Áï½Ã, ½ÇÇàÀ» Ãë¼ÒÇϰí, alert¸¦ Áö¿ì°í portscan.log(Å©±â°¡ 944byte¹Û¿¡ µÇÁö ¾Ê´Â´Ù)¸¸À¸·Î ´Ù½Ã ½ÇÇàÇØºÃÀ¸³ª
5ÃÊÁ¤µµ °É·È´ø °Í °°´Ù. ¹°·Ð ÀÌ ¶§µµ ¸®¼Ò½º»ç¿ë·®Àº ½Ã°£¿¡ ºñ·ÊÇØ ±âÇϱ޼öÀûÀ¸·Î ¿Ã¶ó°¬´Ù.
¼º´ÉÀÌ ³Ê¹« ½Ç¸Á½º·¯¿ö, ¾²Áö ¾Ê±â·Î °áÁ¤Çß´Ù.
snort·Î±×ºÐ¼®ÅøÀ» ¸î°³ ã°í ÀÖ´Ù. ÀÌÁß °¡Àå ±¦ÂúÀº ³ðÀ» ãÀ»¸é À̱ÛÀ» ¾÷µ¥ÀÌÆ®ÇÒ °ÍÀÌ´Ù.
snortSnarf¼³Ä¡°úÁ¤
[root@ns SnortSnarf-010821.1]# cd include/
[root@ns include]# cp -R * /usr/lib/perl5/site_perl/5.005/
[root@ns SnortSnarf-010821.1]# cd cgi/
[root@ns cgi]# cp * /usr/local/apache/cgi-bin/
[root@ns SnortSnarf-010821.1]# cp snortsnarf.pl /usr/local/bin
snortsnarf.pl \
-rulesdir /usr/local/bin/rules \
-rulesfile /usr/local/bin/rules/snort.conf \
-d /webhosting/admin/snort /var/log/snort/alert /var/log/snort/portscan.log
ÂüÁ¶:
http://www.certcc.or.kr/tools/Snort.html
http://www.snort.org
http://www.silicondefense.com/software/snortsnarf/index.htm